GDPR Compliance
Last Updated: February 25, 2026
Introduction
Music Genie is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR). This page explains how we handle personal data for users in the European Economic Area (EEA), United Kingdom, and Switzerland, and how you can exercise your rights under GDPR.
Data Controller
Music Genie operates as the data controller for personal information collected through our platform. For any GDPR-related inquiries, you can contact us at:
Email: [email protected]
Subject Line: GDPR Request
Data Protection Officer (DPO)
While Music Genie's operations do not legally require a designated Data Protection Officer under GDPR Article 37, we have established a dedicated data protection point of contact to handle all privacy-related matters:
Data Protection Contact: [email protected]
Response Times:
- Urgent Matters: Within 72 hours
- Standard Requests: Within 30 days (extendable to 60 days for complex requests)
Our data protection contact is responsible for:
- Monitoring GDPR compliance
- Handling data subject requests
- Coordinating with supervisory authorities
- Advising on data protection impact assessments
EU/UK GDPR Representatives (Article 27)
As a US-based company processing personal data of EEA/UK residents, Music Genie is appointing designated GDPR representatives as required by Article 27:
- EU Representative: [Appointment in progress - contact [email protected]]
- UK Representative: [Appointment in progress - contact [email protected]]
Until representatives are formally designated, all GDPR inquiries may be directed to [email protected]. We will update this page with representative contact details upon appointment.
Lawful Basis for Processing
We process your personal data based on the following lawful bases under GDPR Article 6:
Contract Performance (Article 6(1)(b))
Processing necessary to provide our AI music generation services, manage your account, process payments, and deliver generated content.
Legitimate Interests (Article 6(1)(f))
Processing for fraud prevention, security, service improvement, and analytics. We balance our interests against your rights and freedoms.
Legitimate Interest Assessment (LIA)
For processing based on legitimate interest, we conduct assessments to ensure:
- The processing is necessary for our legitimate purpose
- The processing is balanced against your privacy rights
- You have the right to object to such processing
Examples of legitimate interest processing:
- Fraud prevention and security monitoring
- Network and information security
- Direct marketing to existing customers (with opt-out)
- Product improvement based on anonymized usage data
Consent (Article 6(1)(a))
Marketing communications and non-essential cookies. You can withdraw consent at any time without affecting the lawfulness of prior processing.
Legal Obligation (Article 6(1)(c))
Tax records, fraud prevention requirements, and responding to lawful requests from authorities.
Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
Right of Access
Request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data when there is no compelling reason for continued processing.
Right to Restrict Processing
Request that we limit the processing of your personal data in certain circumstances.
Right to Data Portability
Receive your personal data in a structured, machine-readable format and transfer it to another controller.
Right to Object
Object to processing based on legitimate interests, including profiling and direct marketing.
Rights Related to Automated Decision-Making
Not be subject to decisions based solely on automated processing that significantly affect you.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us using one of the following methods:
- Email: [email protected] with subject line "GDPR Request"
- Account Settings: Access data export and deletion options directly from your dashboard
- Response Time: We will respond within 30 days of receiving your request. For complex requests involving large amounts of data or multiple systems, we may extend this period by an additional 60 days, in which case we will notify you of the extension and the reasons within the initial 30-day period.
We may request verification of your identity before processing your request. There is no fee for most requests, but we may charge a reasonable fee for excessive or unfounded requests.
Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected:
| Data Type | Retention Period |
|---|---|
| Uploaded videos | Deleted within 24 hours of processing |
| Account information | Duration of account + 30 days after deletion |
| Generated music | Until you delete or account closes |
| Payment records | 7 years (legal requirement) |
| Usage analytics | 26 months (anonymized after) |
Data Processing Agreements (DPA)
Enterprise customers may request a Data Processing Agreement (DPA) compliant with GDPR Article 28. Our standard DPA includes:
- Specified processing purposes and instructions
- Sub-processor disclosure and approval requirements
- Data breach notification procedures (within 72 hours as required by GDPR)
- Data deletion upon termination of services
- Audit rights for the data controller
To request our standard DPA template, contact [email protected].
International Data Transfers
Music Genie is based in the United States. When we transfer personal data from the EEA, UK, or Switzerland to the US, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all sub-processors
- Technical and organizational security measures
- Regular assessment of third-party countries' data protection laws
- UK data transfers under the UK GDPR and Data Protection Act 2018
Sub-processors
We use the following sub-processors who may process your data. You will be notified of sub-processor changes with 30 days' notice.
| Provider | Purpose | Location / Safeguards |
|---|---|---|
| Amazon Web Services | Hosting & Storage | US (AWS SCCs) |
| Stripe, Inc. | Payment Processing | US (PCI-DSS, SCCs) |
| PostHog, Inc. | Product Analytics | US (SCCs) |
| SendGrid (Twilio) | Transactional Email | US (SCCs) |
| Cloudflare, Inc. | CDN / Security | Global (SCCs) |
SCCs = Standard Contractual Clauses approved by the European Commission. PCI-DSS = Payment Card Industry Data Security Standard.
Data Protection Impact Assessments (DPIA)
For processing activities that may result in high risk to individuals' rights and freedoms, we conduct Data Protection Impact Assessments in accordance with GDPR Article 35. This includes assessment of:
- New processing technologies or methods
- Large-scale processing of special categories of data
- Systematic monitoring of individuals
- Processing that could significantly affect individuals
AI Music Generation Assessment
Our AI music generation service has been assessed and determined not to constitute high-risk processing because it:
- Does not involve profiling or automated decision-making with legal effects
- Does not process special category data (health, biometric, political opinions, etc.)
- Does not systematically monitor individuals
- Processes video content temporarily (24-hour deletion) solely for music generation
- Maintains user control over all generation parameters and outputs
We maintain records of our DPIAs and will conduct new assessments when introducing significant changes to our processing activities.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in a high risk, we will also notify affected individuals directly.
Right to Lodge a Complaint
If you are not satisfied with how we handle your personal data or your GDPR request, you have the right to lodge a complaint with a supervisory authority. You can contact the supervisory authority in the EU/EEA member state where you reside, where you work, or where the alleged infringement took place.
AI and Automated Processing
Music Genie uses AI to generate music based on your inputs. This processing is necessary for providing our service (contract performance). We want to be transparent about how AI is used:
- Music Generation: AI analyzes video content to generate matching music
- No Profiling: We do not use AI to make decisions that significantly affect you
- No Training on User Data: Your uploaded content is not used to train our AI models
- Transparency: You can request information about how AI processes your content
Cookie Consent
In compliance with the ePrivacy Directive (2009/136/EC) and GDPR requirements for consent:
| Category | Default State | Purpose | Consent Required |
|---|---|---|---|
| Strictly Necessary | Enabled | Authentication, security, essential functionality | No (exempt) |
| Analytics | Disabled | Usage tracking, service improvement (PostHog) | Yes |
| Marketing | Disabled | Advertising, remarketing | Yes |
Consent Management
- Cookie Banner: Displayed on first visit with clear opt-in choices
- Granular Control: Users can accept/reject each category individually
- Preference Storage: Consent choices stored for 12 months
- Easy Withdrawal: Cookie preferences can be changed at any time via account settings or by clicking the cookie icon in the footer
- No Cookie Walls: Access to essential service features is not conditional on accepting non-essential cookies
Third-Party Cookies
We use the following third-party services that may set cookies:
- PostHog: Product analytics (only with consent)
- Stripe: Payment processing (strictly necessary)
For detailed cookie information, see our Cookie Policy.
Contact Us
For any questions about this GDPR Compliance page or our data practices, please contact us at [email protected].
